Linux Foundation Administrators | 1dc9dd5 | 2018-01-26 09:09:09 -0800 | [diff] [blame] | 1 | #!/bin/bash |
| 2 | |
| 3 | # vim: ts=4 sw=4 sts=4 et tw=72 : |
| 4 | |
| 5 | # force any errors to cause the script and job to end in failure |
| 6 | set -xeu -o pipefail |
| 7 | |
| 8 | ensure_kernel_install() { |
| 9 | # Workaround for mkinitrd failing on occassion. |
| 10 | # On CentOS 7 it seems like the kernel install can fail it's mkinitrd |
| 11 | # run quietly, so we may not notice the failure. This script retries for a |
| 12 | # few times before giving up. |
| 13 | initramfs_ver=$(rpm -q kernel | tail -1 | sed "s/kernel-/initramfs-/") |
| 14 | grub_conf="/boot/grub/grub.conf" |
| 15 | # Public cloud does not use /boot/grub/grub.conf and uses grub2 instead. |
| 16 | if [ ! -e "$grub_conf" ]; then |
| 17 | echo "$grub_conf not found. Using Grub 2 conf instead." |
| 18 | grub_conf="/boot/grub2/grub.cfg" |
| 19 | fi |
| 20 | |
| 21 | for i in $(seq 3); do |
| 22 | if grep "$initramfs_ver" "$grub_conf"; then |
| 23 | break |
| 24 | fi |
| 25 | echo "Kernel initrd missing. Retrying to install kernel..." |
| 26 | yum reinstall -y kernel |
| 27 | done |
| 28 | if ! grep "$initramfs_ver" "$grub_conf"; then |
| 29 | cat /boot/grub/grub.conf |
| 30 | echo "ERROR: Failed to install kernel." |
| 31 | exit 1 |
| 32 | fi |
| 33 | } |
| 34 | |
| 35 | ensure_ubuntu_install() { |
| 36 | # Workaround for mirrors occassionally failing to install a package. |
| 37 | # On Ubuntu sometimes the mirrors fail to install a package. This wrapper |
| 38 | # checks that a package is successfully installed before moving on. |
| 39 | |
| 40 | packages=($@) |
| 41 | |
| 42 | for pkg in "${packages[@]}" |
| 43 | do |
| 44 | # Retry installing package 5 times if necessary |
| 45 | for i in {0..5} |
| 46 | do |
| 47 | if [ "$(dpkg-query -W -f='${Status}' "$pkg" 2>/dev/null | grep -c "ok installed")" -eq 0 ]; then |
| 48 | apt-cache policy "$pkg" |
| 49 | apt-get install "$pkg" |
| 50 | continue |
| 51 | else |
| 52 | echo "$pkg already installed." |
| 53 | break |
| 54 | fi |
| 55 | done |
| 56 | done |
| 57 | } |
| 58 | |
| 59 | rh_systems() { |
| 60 | # Handle the occurance where SELINUX is actually disabled |
| 61 | SELINUX=$(grep -E '^SELINUX=(disabled|permissive|enforcing)$' /etc/selinux/config) |
| 62 | MODE=$(echo "$SELINUX" | cut -f 2 -d '=') |
| 63 | case "$MODE" in |
| 64 | permissive) |
| 65 | echo "************************************" |
| 66 | echo "** SYSTEM ENTERING ENFORCING MODE **" |
| 67 | echo "************************************" |
| 68 | # make sure that the filesystem is properly labelled. |
| 69 | # it could be not fully labeled correctly if it was just switched |
| 70 | # from disabled, the autorelabel misses some things |
| 71 | # skip relabelling on /dev as it will generally throw errors |
| 72 | restorecon -R -e /dev / |
| 73 | |
| 74 | # enable enforcing mode from the very start |
| 75 | setenforce enforcing |
| 76 | |
| 77 | # configure system for enforcing mode on next boot |
| 78 | sed -i 's/SELINUX=permissive/SELINUX=enforcing/' /etc/selinux/config |
| 79 | ;; |
| 80 | disabled) |
| 81 | sed -i 's/SELINUX=disabled/SELINUX=permissive/' /etc/selinux/config |
| 82 | touch /.autorelabel |
| 83 | |
| 84 | echo "*******************************************" |
| 85 | echo "** SYSTEM REQUIRES A RESTART FOR SELINUX **" |
| 86 | echo "*******************************************" |
| 87 | ;; |
| 88 | enforcing) |
| 89 | echo "*********************************" |
| 90 | echo "** SYSTEM IS IN ENFORCING MODE **" |
| 91 | echo "*********************************" |
| 92 | ;; |
| 93 | esac |
| 94 | |
| 95 | # Allow jenkins access to alternatives command to switch java version |
| 96 | cat <<EOF >/etc/sudoers.d/89-jenkins-user-defaults |
| 97 | Defaults:jenkins !requiretty |
| 98 | jenkins ALL = NOPASSWD: /usr/sbin/alternatives |
| 99 | EOF |
| 100 | |
| 101 | echo "---> Updating operating system" |
| 102 | yum clean all |
| 103 | yum install -y deltarpm |
| 104 | yum update -y |
| 105 | |
| 106 | ensure_kernel_install |
| 107 | |
| 108 | # add in components we need or want on systems |
| 109 | echo "---> Installing base packages" |
| 110 | yum install -y @base https://dl.fedoraproject.org/pub/epel/epel-release-latest-7.noarch.rpm |
| 111 | # separate group installs from package installs since a non-existing |
| 112 | # group with dnf based systems (F21+) will fail the install if such |
| 113 | # a group does not exist |
| 114 | yum install -y unzip xz puppet git git-review perl-XML-XPath |
Zack Williams | 6156cb2 | 2020-01-22 14:04:00 -0700 | [diff] [blame] | 115 | yum install -y python-{devel,virtualenv} |
| 116 | yum install -y python3-{devel,setuptools,pip} |
Linux Foundation Administrators | 1dc9dd5 | 2018-01-26 09:09:09 -0800 | [diff] [blame] | 117 | |
| 118 | # All of our systems require Java (because of Jenkins) |
| 119 | # Install all versions of the OpenJDK devel but force 1.7.0 to be the |
| 120 | # default |
| 121 | |
| 122 | echo "---> Configuring OpenJDK" |
| 123 | yum install -y 'java-*-openjdk-devel' |
| 124 | |
| 125 | FACTER_OS=$(/usr/bin/facter operatingsystem) |
| 126 | FACTER_OSVER=$(/usr/bin/facter operatingsystemrelease) |
| 127 | case "$FACTER_OS" in |
| 128 | Fedora) |
| 129 | if [ "$FACTER_OSVER" -ge "21" ] |
| 130 | then |
| 131 | echo "---> not modifying java alternatives as OpenJDK 1.7.0 does not exist" |
| 132 | else |
| 133 | alternatives --set java /usr/lib/jvm/jre-1.7.0-openjdk.x86_64/bin/java |
| 134 | alternatives --set java_sdk_openjdk /usr/lib/jvm/java-1.7.0-openjdk.x86_64 |
| 135 | fi |
| 136 | ;; |
| 137 | RedHat|CentOS) |
| 138 | if [ "$(echo "$FACTER_OSVER" | cut -d'.' -f1)" -ge "7" ] |
| 139 | then |
| 140 | echo "---> not modifying java alternatives as OpenJDK 1.7.0 does not exist" |
| 141 | else |
| 142 | alternatives --set java /usr/lib/jvm/jre-1.7.0-openjdk.x86_64/bin/java |
| 143 | alternatives --set java_sdk_openjdk /usr/lib/jvm/java-1.7.0-openjdk.x86_64 |
| 144 | fi |
| 145 | ;; |
| 146 | *) |
| 147 | alternatives --set java /usr/lib/jvm/jre-1.7.0-openjdk.x86_64/bin/java |
| 148 | alternatives --set java_sdk_openjdk /usr/lib/jvm/java-1.7.0-openjdk.x86_64 |
| 149 | ;; |
| 150 | esac |
| 151 | |
| 152 | ######################## |
| 153 | # --- START LFTOOLS DEPS |
| 154 | |
| 155 | # Used by various scripts to push patches to Gerrit |
| 156 | yum install -y git-review |
| 157 | |
| 158 | # Needed to parse OpenStack commands used by opendaylight-infra stack commands |
| 159 | # to initialize Heat template based systems. |
| 160 | yum install -y jq |
| 161 | |
| 162 | # Used by lftools scripts to parse XML |
| 163 | yum install -y xmlstarlet |
| 164 | |
Zack Williams | 6156cb2 | 2020-01-22 14:04:00 -0700 | [diff] [blame] | 165 | # Install Shellcheck from archive |
| 166 | SHELLCHECK_VERSION="v0.6.0" |
| 167 | SHELLCHECK_SHA256SUM="95c7d6e8320d285a9f026b5241f48f1c02d225a1b08908660e8b84e58e9c7dce" |
| 168 | curl -L -o /tmp/shellcheck.tar.xz https://storage.googleapis.com/shellcheck/shellcheck-${SHELLCHECK_VERSION}.linux.x86_64.tar.xz |
| 169 | echo "$SHELLCHECK_SHA256SUM /tmp/shellcheck.tar.xz" | sha256sum -c - |
| 170 | pushd /tmp |
| 171 | tar -xJvf shellcheck.tar.xz |
| 172 | cp shellcheck-${SHELLCHECK_VERSION}/shellcheck /usr/local/bin/shellcheck |
| 173 | chmod a+x /usr/local/bin/shellcheck |
| 174 | popd |
Linux Foundation Administrators | 1dc9dd5 | 2018-01-26 09:09:09 -0800 | [diff] [blame] | 175 | |
| 176 | # --- END LFTOOLS DEPS |
| 177 | ###################### |
| 178 | |
| 179 | # install haveged to avoid low entropy rejecting ssh connections |
| 180 | yum install -y haveged |
| 181 | systemctl enable haveged.service |
| 182 | } |
| 183 | |
| 184 | ubuntu_systems() { |
| 185 | # Ignore SELinux since slamming that onto Ubuntu leads to |
| 186 | # frustration |
| 187 | |
| 188 | # Allow jenkins access to update-alternatives command to switch java version |
| 189 | cat <<EOF >/etc/sudoers.d/89-jenkins-user-defaults |
| 190 | Defaults:jenkins !requiretty |
Zack Williams | 3aa36f9 | 2019-09-20 10:58:16 -0700 | [diff] [blame] | 191 | jenkins ALL = NOPASSWD: /usr/sbin/update-alternatives, /usr/sbin/update-java-alternatives |
| 192 | |
Linux Foundation Administrators | 1dc9dd5 | 2018-01-26 09:09:09 -0800 | [diff] [blame] | 193 | EOF |
| 194 | |
| 195 | export DEBIAN_FRONTEND=noninteractive |
| 196 | cat <<EOF >> /etc/apt/apt.conf |
| 197 | APT { |
| 198 | Get { |
| 199 | Assume-Yes "true"; |
| 200 | allow-change-held-packages "true"; |
| 201 | allow-downgrades "true"; |
| 202 | allow-remove-essential "true"; |
| 203 | }; |
| 204 | }; |
| 205 | |
| 206 | Dpkg::Options { |
| 207 | "--force-confdef"; |
| 208 | "--force-confold"; |
| 209 | }; |
| 210 | |
| 211 | EOF |
| 212 | |
| 213 | # Add hostname to /etc/hosts to fix 'unable to resolve host' issue with sudo |
| 214 | sed -i "/127.0.0.1/s/$/ $(hostname)/" /etc/hosts |
| 215 | |
| 216 | echo "---> Updating operating system" |
| 217 | |
Zack Williams | 889b9f2 | 2019-09-20 09:23:11 -0700 | [diff] [blame] | 218 | # added 2019-09-20 as apt-add-repository and software-properties-common weren't working |
| 219 | cat <<EOF >/etc/apt/sources.list.d/packer.list |
| 220 | # created by packer |
| 221 | deb http://us.archive.ubuntu.com/ubuntu $(lsb_release -sc) main universe restricted multiverse |
| 222 | |
| 223 | EOF |
| 224 | |
Zack Williams | 6057e76 | 2019-09-20 08:59:22 -0700 | [diff] [blame] | 225 | # remove these as the fix seems to be broken now? zdw, 2019-09-20 |
| 226 | # # Change made 2018-07-09 by zdw |
| 227 | # # per discussion on #lf-releng, the upstream Ubuntu image changed to be |
| 228 | # # missing add-apt-repository, so the next command failed. |
| 229 | # apt-get update -m |
| 230 | # # added 2019-09-20, sometimes upstream repos are broken w/this package, try to determine why |
| 231 | # apt-cache madison software-properties-common |
| 232 | # apt-get install -y software-properties-common |
Zack Williams | 852578f | 2018-04-12 14:03:57 -0700 | [diff] [blame] | 233 | |
Linux Foundation Administrators | 1dc9dd5 | 2018-01-26 09:09:09 -0800 | [diff] [blame] | 234 | # add additional repositories |
Zack Williams | 889b9f2 | 2019-09-20 09:23:11 -0700 | [diff] [blame] | 235 | # add-apt-repository "deb http://us.archive.ubuntu.com/ubuntu $(lsb_release -sc) main universe restricted multiverse" |
Linux Foundation Administrators | 1dc9dd5 | 2018-01-26 09:09:09 -0800 | [diff] [blame] | 236 | |
| 237 | echo "---> Installing base packages" |
| 238 | apt-get clean |
| 239 | apt-get update -m |
Zack Williams | 889b9f2 | 2019-09-20 09:23:11 -0700 | [diff] [blame] | 240 | apt-get upgrade -m |
Linux Foundation Administrators | 1dc9dd5 | 2018-01-26 09:09:09 -0800 | [diff] [blame] | 241 | apt-get dist-upgrade -m |
| 242 | |
Andy Bavier | b781c4c | 2018-09-20 08:16:52 -0700 | [diff] [blame] | 243 | apt-get update -m |
Linux Foundation Administrators | 1dc9dd5 | 2018-01-26 09:09:09 -0800 | [diff] [blame] | 244 | ensure_ubuntu_install unzip xz-utils puppet git libxml-xpath-perl |
| 245 | |
Zack Williams | 1b00d40 | 2019-07-22 17:17:10 -0700 | [diff] [blame] | 246 | # Deprecated - updating to corretto Java distro, 2019-07-22, zdw |
Linux Foundation Administrators | 1dc9dd5 | 2018-01-26 09:09:09 -0800 | [diff] [blame] | 247 | # install Java 7 |
Zack Williams | 1b00d40 | 2019-07-22 17:17:10 -0700 | [diff] [blame] | 248 | # echo "---> Configuring OpenJDK" |
| 249 | # FACTER_OSVER=$(/usr/bin/facter operatingsystemrelease) |
| 250 | # case "$FACTER_OSVER" in |
| 251 | # 14.04) |
| 252 | # apt-get install openjdk-7-jdk |
| 253 | # # make jdk8 available |
| 254 | # add-apt-repository -y ppa:openjdk-r/ppa |
| 255 | # apt-get update |
| 256 | # # We need to force openjdk-8-jdk to install |
| 257 | # apt-get install openjdk-8-jdk |
| 258 | # # make sure that we still default to openjdk 7 |
| 259 | # update-alternatives --set java /usr/lib/jvm/java-7-openjdk-amd64/jre/bin/java |
| 260 | # update-alternatives --set javac /usr/lib/jvm/java-7-openjdk-amd64/bin/javac |
| 261 | # ;; |
| 262 | # 16.04) |
| 263 | # apt-get install openjdk-8-jdk |
| 264 | # ;; |
| 265 | # *) |
| 266 | # echo "---> Unknown Ubuntu version $FACTER_OSVER" |
| 267 | # exit 1 |
| 268 | # ;; |
| 269 | # esac |
| 270 | ######################## |
| 271 | |
| 272 | echo "---> Configuring Corretto JDK Distribution" |
| 273 | # instructions: https://docs.aws.amazon.com/corretto/latest/corretto-8-ug/generic-linux-install.html |
| 274 | # install prereqs |
| 275 | apt-get install java-common |
| 276 | |
| 277 | # install Java8 |
| 278 | CORRETTO_JAVA8_VERSION="8.222.10-1" |
| 279 | CORRETTO_JAVA8_SHA256SUM="e5fd6c6f2d1a1fc5e6926f7a543e67ad0f0e0389ddc5d2deb5890bdeb21ea445" |
| 280 | curl -L -o /tmp/corretto_java8.deb "https://d3pxv6yz143wms.cloudfront.net/$(echo $CORRETTO_JAVA8_VERSION | tr - .)/java-1.8.0-amazon-corretto-jdk_${CORRETTO_JAVA8_VERSION}_amd64.deb" |
| 281 | echo "$CORRETTO_JAVA8_SHA256SUM /tmp/corretto_java8.deb" | sha256sum -c - |
| 282 | dpkg -i /tmp/corretto_java8.deb |
| 283 | |
| 284 | # install Java11 |
| 285 | CORRETTO_JAVA11_VERSION="11.0.4.11-1" |
| 286 | CORRETTO_JAVA11_SHA256SUM="f47c77f8f9ee5a80804765236c11dc749d351d3b8f57186c6e6b58a6c4019d3e" |
| 287 | curl -L -o /tmp/corretto_java11.deb "https://d3pxv6yz143wms.cloudfront.net/$(echo $CORRETTO_JAVA11_VERSION | tr - .)/java-11-amazon-corretto-jdk_${CORRETTO_JAVA11_VERSION}_amd64.deb" |
| 288 | echo "$CORRETTO_JAVA11_SHA256SUM /tmp/corretto_java11.deb" | sha256sum -c - |
| 289 | dpkg -i /tmp/corretto_java11.deb |
| 290 | |
Zack Williams | 52b4cb6 | 2019-08-30 08:09:07 -0700 | [diff] [blame] | 291 | # Fix corretto 11 lack of jinfo that prevents update-java-alternatives from working |
| 292 | # Upstream fix not integrated yet: https://github.com/corretto/corretto-11/pull/27 |
| 293 | cat <<EOF >/usr/lib/jvm/.java-11-amazon-corretto.jinfo |
| 294 | name=java-11-amazon-corretto |
| 295 | alias=java-11-amazon-corretto |
| 296 | priority=11100002 |
| 297 | section=main |
| 298 | |
| 299 | jdk java /usr/lib/jvm/java-11-amazon-corretto/bin/java |
| 300 | jdk keytool /usr/lib/jvm/java-11-amazon-corretto/bin/keytool |
| 301 | jdk rmid /usr/lib/jvm/java-11-amazon-corretto/bin/rmid |
| 302 | jdk rmiregistry /usr/lib/jvm/java-11-amazon-corretto/bin/rmiregistry |
| 303 | jdk jjs /usr/lib/jvm/java-11-amazon-corretto/bin/jjs |
| 304 | jdk pack200 /usr/lib/jvm/java-11-amazon-corretto/bin/pack200 |
| 305 | jdk unpack200 /usr/lib/jvm/java-11-amazon-corretto/bin/unpack200 |
| 306 | jdk javac /usr/lib/jvm/java-11-amazon-corretto/bin/javac |
| 307 | jdk jaotc /usr/lib/jvm/java-11-amazon-corretto/bin/jaotc |
| 308 | jdk jlink /usr/lib/jvm/java-11-amazon-corretto/bin/jlink |
| 309 | jdk jmod /usr/lib/jvm/java-11-amazon-corretto/bin/jmod |
| 310 | jdk jhsdb /usr/lib/jvm/java-11-amazon-corretto/bin/jhsdb |
| 311 | jdk jar /usr/lib/jvm/java-11-amazon-corretto/bin/jar |
| 312 | jdk jarsigner /usr/lib/jvm/java-11-amazon-corretto/bin/jarsigner |
| 313 | jdk javadoc /usr/lib/jvm/java-11-amazon-corretto/bin/javadoc |
| 314 | jdk javap /usr/lib/jvm/java-11-amazon-corretto/bin/javap |
| 315 | jdk jcmd /usr/lib/jvm/java-11-amazon-corretto/bin/jcmd |
| 316 | jdk jconsole /usr/lib/jvm/java-11-amazon-corretto/bin/jconsole |
| 317 | jdk jdb /usr/lib/jvm/java-11-amazon-corretto/bin/jdb |
| 318 | jdk jdeps /usr/lib/jvm/java-11-amazon-corretto/bin/jdeps |
| 319 | jdk jdeprscan /usr/lib/jvm/java-11-amazon-corretto/bin/jdeprscan |
| 320 | jdk jimage /usr/lib/jvm/java-11-amazon-corretto/bin/jimage |
| 321 | jdk jinfo /usr/lib/jvm/java-11-amazon-corretto/bin/jinfo |
| 322 | jdk jmap /usr/lib/jvm/java-11-amazon-corretto/bin/jmap |
| 323 | jdk jps /usr/lib/jvm/java-11-amazon-corretto/bin/jps |
| 324 | jdk jrunscript /usr/lib/jvm/java-11-amazon-corretto/bin/jrunscript |
| 325 | jdk jshell /usr/lib/jvm/java-11-amazon-corretto/bin/jshell |
| 326 | jdk jstack /usr/lib/jvm/java-11-amazon-corretto/bin/jstack |
| 327 | jdk jstat /usr/lib/jvm/java-11-amazon-corretto/bin/jstat |
| 328 | jdk jstatd /usr/lib/jvm/java-11-amazon-corretto/bin/jstatd |
| 329 | jdk rmic /usr/lib/jvm/java-11-amazon-corretto/bin/rmic |
| 330 | jdk serialver /usr/lib/jvm/java-11-amazon-corretto/bin/serialver |
| 331 | |
| 332 | EOF |
| 333 | |
Zack Williams | 1b00d40 | 2019-07-22 17:17:10 -0700 | [diff] [blame] | 334 | # Set default version to be Java8 |
Zack Williams | 52b4cb6 | 2019-08-30 08:09:07 -0700 | [diff] [blame] | 335 | update-java-alternatives --set java-1.8.0-amazon-corretto |
Zack Williams | 1b00d40 | 2019-07-22 17:17:10 -0700 | [diff] [blame] | 336 | |
| 337 | # Set default version to be Java11 |
Zack Williams | 52b4cb6 | 2019-08-30 08:09:07 -0700 | [diff] [blame] | 338 | # update-java-alternatives --set java-11-amazon-corretto |
Linux Foundation Administrators | 1dc9dd5 | 2018-01-26 09:09:09 -0800 | [diff] [blame] | 339 | |
| 340 | ######################## |
| 341 | # --- START LFTOOLS DEPS |
| 342 | |
| 343 | # Used by various scripts to push patches to Gerrit |
| 344 | ensure_ubuntu_install git-review |
| 345 | |
| 346 | # Needed to parse OpenStack commands used by opendaylight-infra stack commands |
| 347 | # to initialize Heat template based systems. |
| 348 | ensure_ubuntu_install jq |
| 349 | |
| 350 | # Used by lftools scripts to parse XML |
| 351 | ensure_ubuntu_install xmlstarlet |
| 352 | |
Zack Williams | ae52f5e | 2018-04-12 11:47:57 -0700 | [diff] [blame] | 353 | # Change made by zdw on 2018-04-12 |
| 354 | # hackage.haskell.org was down, talked to zxiiro on #lf-releng and he recommended |
| 355 | # pulling down the packages in a way similar to this ansible role, rather than using cabal: |
| 356 | # https://github.com/lfit/ansible-roles-shellcheck-install/blob/master/tasks/main.yml |
Linux Foundation Administrators | 1dc9dd5 | 2018-01-26 09:09:09 -0800 | [diff] [blame] | 357 | |
Zack Williams | 1b00d40 | 2019-07-22 17:17:10 -0700 | [diff] [blame] | 358 | SHELLCHECK_VERSION="v0.6.0" |
| 359 | SHELLCHECK_SHA256SUM="95c7d6e8320d285a9f026b5241f48f1c02d225a1b08908660e8b84e58e9c7dce" |
Zack Williams | ae52f5e | 2018-04-12 11:47:57 -0700 | [diff] [blame] | 360 | curl -L -o /tmp/shellcheck.tar.xz https://storage.googleapis.com/shellcheck/shellcheck-${SHELLCHECK_VERSION}.linux.x86_64.tar.xz |
| 361 | echo "$SHELLCHECK_SHA256SUM /tmp/shellcheck.tar.xz" | sha256sum -c - |
| 362 | pushd /tmp |
| 363 | tar -xJvf shellcheck.tar.xz |
| 364 | cp shellcheck-${SHELLCHECK_VERSION}/shellcheck /usr/local/bin/shellcheck |
| 365 | chmod a+x /usr/local/bin/shellcheck |
| 366 | popd |
Linux Foundation Administrators | 1dc9dd5 | 2018-01-26 09:09:09 -0800 | [diff] [blame] | 367 | |
| 368 | # --- END LFTOOLS DEPS |
| 369 | ###################### |
| 370 | |
| 371 | # install haveged to avoid low entropy rejecting ssh connections |
| 372 | apt-get install haveged |
| 373 | update-rc.d haveged defaults |
| 374 | |
| 375 | # disable unattended upgrades & daily updates |
| 376 | echo '---> Disabling automatic daily upgrades' |
| 377 | sed -ine 's/"1"/"0"/g' /etc/apt/apt.conf.d/10periodic |
| 378 | echo 'APT::Periodic::Unattended-Upgrade "0";' >> /etc/apt/apt.conf.d/10periodic |
| 379 | } |
| 380 | |
| 381 | all_systems() { |
| 382 | # Do any Distro specific installations here |
| 383 | echo "Checking distribution" |
| 384 | FACTER_OS=$(/usr/bin/facter operatingsystem) |
| 385 | case "$FACTER_OS" in |
| 386 | *) |
| 387 | echo "---> $FACTER_OS found" |
| 388 | echo "No extra steps for $FACTER_OS" |
| 389 | ;; |
| 390 | esac |
| 391 | } |
| 392 | |
| 393 | echo "---> Attempting to detect OS" |
| 394 | # upstream cloud images use the distro name as the initial user |
| 395 | ORIGIN=$(if [ -e /etc/redhat-release ] |
| 396 | then |
| 397 | echo redhat |
| 398 | else |
| 399 | echo ubuntu |
| 400 | fi) |
| 401 | #ORIGIN=$(logname) |
| 402 | |
| 403 | case "${ORIGIN}" in |
| 404 | fedora|centos|redhat) |
| 405 | echo "---> RH type system detected" |
| 406 | rh_systems |
| 407 | ;; |
| 408 | ubuntu) |
| 409 | echo "---> Ubuntu system detected" |
| 410 | ubuntu_systems |
| 411 | ;; |
| 412 | *) |
| 413 | # Kill the build for unhandled distributions |
| 414 | echo "---> Unknown operating system" 1>&2 |
| 415 | exit 1 |
| 416 | ;; |
| 417 | esac |
| 418 | |
| 419 | # execute steps for all systems |
| 420 | all_systems |